CVE-2018-19694

HMS Industrial Networks Netbiter WS100 3.30.5 devices and previous have reflected XSS in the login form.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:hms-networks:netbiter_ws100_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:hms-networks:netbiter_ws100:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:hms-networks:netbiter_ws200_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:hms-networks:netbiter_ws200:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:hms-networks:netbiter_ec150_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:hms-networks:netbiter_ec150:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:hms-networks:netbiter_ec250_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:hms-networks:netbiter_ec250:-:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:o:hms-networks:netbiter_lc310_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:hms-networks:netbiter_lc310:-:*:*:*:*:*:*:*

Configuration 6 (hide)

AND
cpe:2.3:o:hms-networks:netbiter_lc310_thingworx_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:hms-networks:netbiter_lc310_thingworx:-:*:*:*:*:*:*:*

Configuration 7 (hide)

AND
cpe:2.3:o:hms-networks:netbiter_lc350_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:hms-networks:netbiter_lc350:-:*:*:*:*:*:*:*

Configuration 8 (hide)

AND
cpe:2.3:o:hms-networks:netbiter_lc350_thingworx_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:hms-networks:netbiter_lc350_thingworx:-:*:*:*:*:*:*:*

History

No history.

Information

Published : 2019-03-21 16:00

Updated : 2024-02-04 20:20


NVD link : CVE-2018-19694

Mitre link : CVE-2018-19694

CVE.ORG link : CVE-2018-19694


JSON object : View

Products Affected

hms-networks

  • netbiter_ec150
  • netbiter_lc350
  • netbiter_ec250
  • netbiter_lc310
  • netbiter_ws100
  • netbiter_ws200_firmware
  • netbiter_lc310_thingworx
  • netbiter_lc350_thingworx
  • netbiter_lc310_firmware
  • netbiter_ec150_firmware
  • netbiter_lc310_thingworx_firmware
  • netbiter_lc350_firmware
  • netbiter_ws100_firmware
  • netbiter_lc350_thingworx_firmware
  • netbiter_ws200
  • netbiter_ec250_firmware
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')